Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill advertises significant capabilities—network access, environment use, and filesystem read/write—without declaring corresponding permissions or clearly constraining them. This undermines least-privilege review and can cause operators to approve a skill without understanding that it can persist data, inspect local context, or make outbound requests.
